โ† All ACFE Flashcard Decks

Digital Forensics and Evidence Flashcards

7 cards from real ACFE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Digital Forensics and Evidence flashcards as text
  1. What is 'anti-forensics' and why is it relevant to fraud examiners?

    Answer: Methods used to destroy, hide, or alter digital evidence to impede investigations

    Anti-forensics encompasses techniques like data wiping, timestamp manipulation, and encryption that suspects use to obstruct forensic examination.

  2. Which Windows registry hive contains information about recently accessed USB devices?

    Answer: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR

    The USBSTOR key records the vendor, product, and serial number of every USB storage device ever connected to the system.

  3. In digital evidence handling, what is a 'forensic image' as opposed to a simple file copy?

    Answer: A sector-by-sector duplicate that captures all data including unallocated space

    A forensic image is a bit-for-bit copy of every sector on a storage device, preserving deleted files, slack space, and other artifacts a file copy would miss.

  4. A fraud examiner finds that critical log files on a corporate server were deleted two hours after an internal audit was announced. What forensic concept is most relevant?

    Answer: Spoliation of evidence

    Spoliation is the intentional or negligent destruction of evidence, which can result in adverse inference instructions or sanctions against the spoliating party.

  5. What type of data exists in a storage device's unallocated space?

    Answer: Fragments of previously deleted files that have not been overwritten

    Unallocated space contains remnants of deleted files whose sectors have not yet been reused, making it a rich source of recoverable evidence.

  6. Which of the following is an example of volatile data that must be collected first at a live fraud scene?

    Answer: Contents of RAM including running processes and open network connections

    RAM is volatile and its contents are lost when a system is powered off, so live system memory must be captured before any shutdown.

  7. How can metadata embedded in a Microsoft Word document assist a fraud examiner?

    Answer: It can expose the author's name, revision history, and creation date

    Word document metadata (stored in document properties) often includes the original author, last editor, total editing time, and revision dates that can contradict a suspect's claims.